58.586 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.586 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-47281 | CRIT 9.6 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-44616 | MED 6.5 | apache zeppelin LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint | 0,8% | — |
| CVE-2026-40861 | MED 6.5 | apache airflow A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (read-path attack — e.g. `/etc/passwd` or `airflow.cfg`) or (b) supply a `task_id` containing `..` sequences accept | 0,8% | — |
| CVE-2025-27483 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0,8% | — |
| CVE-2024-47604 | HIGH 8.2 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser. | 0,8% | — |
| CVE-2024-27784 | HIGH 8.8 | fortinet fortiaiops Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files. | 0,8% | — |
| CVE-2023-36418 | HIGH 7.8 | microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-22192 | HIGH 7.5 | juniper junos_os_evolved An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an incoming TCP packet destined to | 0,8% | — |
| CVE-2025-21193 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0,8% | — |
| CVE-2024-46737 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix kernel crash if commands allocation fails If the commands allocation fails in nvmet_tcp_alloc_cmds() the kernel crashes in nvmet_tcp_release_queue_work() because of a NULL poi | 0,8% | — |
| CVE-2024-40980 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drop_monitor: replace spin_lock by raw_spin_lock trace_drop_common() is called with preemption disabled, and it acquires a spin_lock. This is problematic for RT kernels because spin_locks ar | 0,8% | — |
| CVE-2024-21309 | HIGH 7.8 | microsoft windows_11_21h2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-20682 | HIGH 7.8 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2023-47703 | MED 5.3 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Forc | 0,8% | — |
| CVE-2023-28365 | CRIT 9.1 | ui unifi_network_application A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored. | 0,8% | — |
| CVE-2020-26077 | MED 4.3 | cisco iot_field_network_director A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to imp | 0,8% | — |
| CVE-2018-1087 | HIGH 8.0 | canonical ubuntu_linux kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS | 0,8% | — |
| CVE-2015-0674 | MED 6.1 | cisco cloud_web_security Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | 0,8% | — |
| CVE-2026-81377 | MED 6.5 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | 0,8% | — |
| CVE-2026-69806 | HIGH 7.0 | microsoft .net Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | 0,8% | — |
| CVE-2026-62801 | MED 6.5 | microsoft windows_10_1607 Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network. | 0,8% | — |
| CVE-2026-47287 | MED 6.5 | microsoft visual_studio_code Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | 0,8% | — |
| CVE-2026-46745 | MED 5.3 | apache apache-airflow-providers-fab Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade i | 0,8% | — |
| CVE-2026-41090 | CRIT 9.3 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 0,8% | — |
| CVE-2026-30912 | HIGH 7.5 | apache airflow In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, wh | 0,8% | — |